“View Document”

Credentials and AAA

Sometimes a cyber-attack is something as easy as adding a button saying “view document” when whale phishing senior people in an organisation. Ongoing Microsoft Azure account hijacking campaign targets executives (bleepingcomputer.com) Your takeaway When was the last time you audited the credentials and associated authorisations of those credentials? If you …

The truth about keyloggers and how easy it is to get the unwary to download one…

This is an excellent article by Xavier Mertens, with a video that demonstrates how a keylogger on your computer will defeat even the most complex of passwords. A Python MP3 Player with Builtin Keylogger Capability – SANS Internet Storm Center Your takeaway from this Have a policy in place stating …